Cybersecurity-2020年云安全报告(英文)-2020.8-20页_1mb
报告摘要
2020 Cloud Security Report Summary
Introduction
Companies are rapidly migrating workloads to the cloud to benefit from increased efficiency, scalability, and faster deployments. However, cloud security concerns remain high, especially in the wake of the 2020 COVID crisis, which accelerated the shift to remote work environments.
Key Survey Findings
- Security Concerns: 94% of cybersecurity professionals are at least moderately concerned about public cloud security, showing a slight increase from the previous year.
- Barriers to Cloud Adoption: The biggest barrier to cloud adoption is the lack of qualified staff (37%), up from fifth place last year. Other top barriers include integration with existing IT environments (35%) and data security issues (35%).
- Training and Certifications: Training and certifying IT staff (61%) is the primary tactic used to meet evolving security needs. 58% rely on native cloud security tools, and 34% plan to hire more cloud security staff.
- Budget Allocation: 60% of organizations expect an increase in their cloud security budget over the next 12 months. On average, 27% of their total security budget is allocated to cloud security.
- Security Readiness: 69% of organizations rate their team's security readiness as average or below average, while only 31% rate it as above average. 80% of these believe their teams would benefit from cloud security training and certification.
- Security Awareness Gap: Cybersecurity professionals agree that 59% of employees would benefit from security training and certification for their jobs.
Cloud Security Concerns
- Data Loss/Leakage (69%): The top concern, up five percentage points from last year.
- Data Privacy/Confidentiality (66%): Second major concern, up four percentage points.
- Accidental Exposure of Credentials (44%): Third concern, up from 29% last year.
- Incident Response (44%): Also a major concern.
- Legal & Regulatory Compliance (35%): A significant concern for many.
Operational Security Headaches
- Lack of Qualified Staff (47%): The top operational challenge.
- Compliance (40%): Second challenge.
- Setting Consistent Security Policies (36%): Third challenge.
- Other concerns include visibility into infrastructure security, inability to identify misconfigurations quickly, and security not keeping up with application changes.
Biggest Cloud Security Threats
- Misconfiguration of the Cloud Platform (68%): Ranked highest, up from third place last year.
- Unauthorized Access (58%): Second major threat.
- Insecure Interfaces/APIs (52%) and Account Hijacking (50%) follow closely.
- Other threats include external data sharing, malicious insiders, and foreign cyber attacks.
Traditional Tools in the Cloud
- 82% of respondents say traditional security tools either don't work at all in the cloud or have limited functionality, indicating a significant gap in tool effectiveness for cloud environments.
Drivers of Cloud-Based Security Solutions
- Faster Time to Deployment (41%) and Cost Savings (41%) are the main drivers.
- Other drivers include reduced patching efforts (40%), better visibility into user activity, secure app access from any location, and meeting compliance expectations.
Barriers to Cloud-Based Security Adoption
- Staff Expertise/Training (55%) is the top barrier.
- Budget Constraints (46%) and Data Privacy Concerns (37%) follow.
- Other barriers include lack of integration with on-premises platforms (36%), solution maturity (30%), and regulatory compliance requirements (29%).
Cloud Benefits Realized
- Flexible Capacity/Scalability (51%): The most commonly realized benefit.
- Improved Availability (46%) and Increased Agility (45%) are also widely recognized.
- Other benefits include accelerated deployment, reduced cost, and increased geographic reach.
Paths to Stronger Cloud Security
- Training and Certification (61%) is the primary tactic to address security needs.
- Native Cloud Tools (58%) and Hiring Dedicated Staff (34%) are also key strategies.
- Organizations are also considering deploying third-party security software and partnering with Managed Security Services Providers (MSSP).
Security Training and Certification
- Training Demand: 80% of organizations with average or below average security readiness believe training and certification would benefit their teams.
- Certifications: The top 10 most valued security certifications include CISSP, CISM, CCSK, Security+, CISA, CRISC, CCSP, Network+, GSEC, and others.
- Training Focus: Cybersecurity professionals prioritize Cloud-Enabled Cybersecurity (66%), followed by Application Security (45%) and Risk-Based Frameworks (43%).
Methodology & Demographics
- The report is based on a survey of 653 cybersecurity professionals conducted in May 2020.
- Respondents include technical executives and IT security practitioners across various industries and company sizes.
(ISC)²
- (ISC)² is an international nonprofit organization known for the CISSP certification.
- It partnered with the Cloud Security Alliance to launch the CCSP certification, which is now its fastest-growing credential.
- The organization emphasizes training, certifications, and education to enhance cloud security practices.
展开完整摘要
试读结束,高清完整版pdf/doc/ppt,请点下载